CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,134 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0306 EXP | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Back… | Patch early | 5.0 medium | 12.5% | 2006-01-19 |
| CVE-2006-2554 EXP | Buffer overflow in the tell_player_surr_changes function in Genecys 0.2 and earlier might allow remote attackers to execute arbitrary code via long ar… | Patch early | 6.4 medium | 12.5% | 2006-05-24 |
| CVE-2006-1260 EXP | Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which… | Patch early | 5.0 medium | 12.5% | 2006-03-19 |
| CVE-2005-3507 EXP | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" se… | Patch early | 5.0 medium | 12.4% | 2005-11-06 |
| CVE-2021-25155 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 6.5 medium | 12.4% | 2021-03-30 |
| CVE-2006-1015 EXP | Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additi… | Patch early | 6.4 medium | 12.4% | 2006-03-07 |
| CVE-2017-0785 EXP | A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1… | Patch early | 6.5 medium | 12.4% | 2017-09-14 |
| CVE-2013-3690 EXP | Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and pos… | Patch early | 6.8 medium | 12.4% | 2013-10-01 |
| CVE-2004-1675 EXP | Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DO… | Patch early | 5.0 medium | 12.4% | 2004-09-11 |
| CVE-2016-4314 EXP | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary fil… | Patch early | 4.9 medium | 12.4% | 2017-02-17 |
| CVE-2009-4496 EXP | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 12.3% | 2010-01-13 |
| CVE-2008-6172 EXP | Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is dis… | Patch early | 6.8 medium | 12.3% | 2009-02-19 |
| CVE-2007-3655 EXP | Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attacker… | Patch early | 6.8 medium | 12.3% | 2007-07-10 |
| CVE-2009-0192 EXP | Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute… | Patch early | 5.0 medium | 12.3% | 2009-07-14 |
| CVE-2004-0465 EXP | Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys wit… | Patch early | 5.0 medium | 12.3% | 2004-12-31 |
| CVE-2019-17554 EXP | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Reque… | Patch early | 5.5 medium | 12.2% | 2019-12-04 |
| CVE-2018-15705 EXP | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a… | Patch early | 6.5 medium | 12.2% | 2018-10-31 |
| CVE-2010-3679 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLO… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3681 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3683 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authe… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3680 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3678 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL argu… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2020-15500 EXP | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response… | Patch early | 6.1 medium | 12.2% | 2020-07-01 |
| CVE-2009-1970 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 5.0 medium | 12.2% | 2009-07-14 |
| CVE-2003-0801 EXP | Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal… | Patch early | 4.3 medium | 12.2% | 2003-10-06 |
| CVE-2007-0908 EXP | The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a nu… | Patch early | 5.0 medium | 12.2% | 2007-02-13 |
| CVE-2017-14955 EXP | Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to… | Patch early | 5.9 medium | 12.1% | 2017-10-02 |
| CVE-2018-19040 EXP | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir… | Patch early | 5.3 medium | 12.1% | 2019-01-31 |
| CVE-2010-0295 EXP | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a deni… | Patch early | 5.0 medium | 12.1% | 2010-02-03 |
| CVE-2019-1244 EXP | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… | Patch early | 6.5 medium | 12.1% | 2019-09-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt